Hack 3.8.12 Joomla

Discussion regarding Joomla! 3.x security issues.

Moderators: Bernard T, mandville, fcoulter, PhilD, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Post Reply
Kenechard
Joomla! Fledgling
Joomla! Fledgling
Posts: 1
Joined: Mon Oct 15, 2018 4:38 pm

Hack 3.8.12 Joomla

Post by Kenechard » Mon Oct 15, 2018 4:59 pm

We are dealing with a hack on one of our sites. Here is what is happening. We currently know that a file was added to the site somehow. We were able to track down this and also it also seems to be creating a file. The source code file was added to /public_html/libraries and the file generated from that is added to public_html. We have the files but sadly they are a bit more complicated then what I'm used to. I'll post it in the attachments. The type of hack is/was as I understand it a keyword hack which spams google searches with links in other languages. We have determined that there are not files set to 777 or 755 access otherwise here is the source code and the file which was generated. I did some digging into other sites for what this could be and also attempt some decryptions to see if there was anything about this online with little return from it. If you are worried about this being an issues file I"ll post the start of the source code where so you can see something before attempting a download.

[ redacted ]

This goes on for a very long length.

Any thoughts would be helpful.

Thanks,
Last edited by toivo on Mon Oct 15, 2018 5:26 pm, edited 1 time in total.
Reason: mod note: hack code and attachment deleted

User avatar
Webdongle
Joomla! Master
Joomla! Master
Posts: 36152
Joined: Sat Apr 05, 2008 9:58 pm

Re: Hack 3.8.12 Joomla

Post by Webdongle » Mon Oct 15, 2018 5:32 pm

http://www.weblinksonline.co.uk/
https://www.weblinksonline.co.uk/updating-joomla.html
"The definition of insanity is doing the same thing over and over again, but expecting different results": Albert Einstein

User avatar
leolam
Joomla! Master
Joomla! Master
Posts: 19139
Joined: Mon Aug 29, 2005 10:17 am
Location: Netherlands/ UK/ S'pore/Jakarta/ North America
Contact:

Re: Hack 3.8.12 Joomla

Post by leolam » Mon Oct 22, 2018 10:46 am

Visit myjoomla.com First scan is free and hire Phil to clean up the mess. He is a Pro.

Leo 8)
Joomla's #1 Professional Support Provider:
-> Joomla Professional Support: https://gws-desk.com -
-> Joomla Specialized Hosting Solutions: https://gws-host.com -
Member Joomla Bug Squad & Joomla CMS Release Team

User avatar
JAVesey
Joomla! Ace
Joomla! Ace
Posts: 1845
Joined: Tue May 14, 2013 1:21 pm
Location: Cardiff, Wales, UK
Contact:

Re: Hack 3.8.12 Joomla

Post by JAVesey » Mon Oct 22, 2018 4:17 pm

leolam wrote:
Mon Oct 22, 2018 10:46 am
Visit myjoomla.com First scan is free and hire Phil to clean up the mess. He is a Pro.

Leo 8)
No reply from the OP for over a week. You're wasting your time with this, I fear.
John V
Cardiff, Wales, UK
Uses Joomla 3.9.1

User avatar
leolam
Joomla! Master
Joomla! Master
Posts: 19139
Joined: Mon Aug 29, 2005 10:17 am
Location: Netherlands/ UK/ S'pore/Jakarta/ North America
Contact:

Re: Hack 3.8.12 Joomla

Post by leolam » Sun Nov 25, 2018 3:34 pm

Sometimes people are so thankful for the help they receive

Leo 8)
Joomla's #1 Professional Support Provider:
-> Joomla Professional Support: https://gws-desk.com -
-> Joomla Specialized Hosting Solutions: https://gws-host.com -
Member Joomla Bug Squad & Joomla CMS Release Team


Post Reply

Return to “Security in Joomla! 3.x”